Security at Fintech Farm

Report a
vulnerability.

We build and run banking software across six markets. If you have found a security vulnerability in any Fintech Farm product, tell us β€” we will respond promptly and in good faith.
5
business days

to acknowledge
10
business days

to initial assessment
90
days

coordinated disclosure
πŸ“¬
Report a
vulnerability
security@fintech-farm.com
Monitored Mon–Fri, 09:00–18:00 UTC+2
Please include in your report
β€”
The affected product, URL, or API and where you encountered the issue.
β€”
Clear steps to reproduce and the impact you were able to demonstrate.
β€”
Any proof-of-concept, request/response samples, or screenshots.
β€”
How you would like to be credited, if you want acknowledgement.
To send an encrypted report, email us first and we will arrange a secure channel.
🎯
Scope
These are the systems we want reports on, and the testing we ask you not to perform.
In scope
βœ“
Mobile applications
βœ“
Web applications
βœ“
Public APIs
βœ“
Backend services
βœ“
SDKs and integration libraries
βœ“
Authentication infrastructure
Out of scope
Γ—
Third-party services we don't operate
Γ—
Denial-of-service testing
Γ—
Social engineering of our people
Γ—
Physical attacks
Γ—
Theoretical issues without a realistic proof of concept
πŸ›‘οΈ
Safe harbour
We will not pursue or support legal action against security researchers who discover and report vulnerabilities in good faith and in accordance with this policy.
Research and reporting carried out consistently with this policy are considered authorised. We ask that you make a good-faith effort to avoid privacy violations, data destruction, and interruption of our services; that you access or modify only the minimum data needed to demonstrate the issue; and that you give us reasonable time to remediate before any public disclosure.
πŸ”„
What to
expect
We practise coordinated disclosure. All timelines can be adjusted by mutual agreement.
Day 0
You report
We receive your report at security@fintech-farm.com.
≀ 5 business days
Acknowledgement
We confirm receipt and open a tracking record.
≀ 10 business days
Assessment
We validate, triage severity, and share next steps.
≀ 90 days
Disclosure
We remediate and disclose together by default within 90 days.
πŸ“‹
Security
advisories
We publish advisories for security-relevant updates and notify affected bank partners directly through our standard delivery channel. When a fix is not yet available, we publish interim mitigation guidance here.
No advisories at this time.
Security update notices and interim mitigation guidance will be posted here.